Back to search
CVE-2009-2624
Published: Jan 29, 2010
Modified: Aug 7, 2024
PUBLISHED
Description
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://support.apple.com/kb/HT4435
x_refsource_CONFIRM
ADV-2010-0185
vdb-entry
x_refsource_VUPEN
USN-889-1
vendor-advisory
x_refsource_UBUNTU
https://bugzilla.redhat.com/show_bug.cgi?id=514711
x_refsource_CONFIRM
[bug-gzip] 20091002 gzip-1.3.13 released [major]
mailing-list
x_refsource_MLIST
APPLE-SA-2010-11-10-1
vendor-advisory
x_refsource_APPLE
DSA-1974
vendor-advisory
x_refsource_DEBIAN
MDVSA-2010:020
vendor-advisory
x_refsource_MANDRIVA
38223
third-party-advisory
x_refsource_SECUNIA
38132
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2010:008
vendor-advisory
x_refsource_SUSE
38232
third-party-advisory
x_refsource_SECUNIA
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507263
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now